SCS-C02 exam dumps

SCS-C02 practice question 349 of 504

AWS Certified Security - Specialty. Expert level, Amazon Web Services. Free question with the correct answer and a full explanation.

SCS-C02 Question 349

Select 3

An organization is hosting a web application behind an Application Load Balancer (ALB) in AWS. They want to secure the application using HTTPS and ensure the TLS certificate is correctly configured to work with the ALB. Which steps must the organization take to achieve this?

  1. A

    Request or import a TLS certificate into AWS Certificate Manager (ACM) or upload it into IAM.

  2. B

    Assign the TLS certificate to the Application Load Balancer's HTTPS listener.

  3. C

    Ensure the web application server contains a copy of the same TLS certificate used by the ALB.

  4. D

    Configure a security group to allow inbound HTTPS traffic to the Application Load Balancer.

  5. E

    Enable Server Name Indication (SNI) on the Application Load Balancer to support multiple TLS certificates.

Show answer and explanation

Correct answers: A, B, D

Explanation

To secure an application behind an Application Load Balancer with HTTPS, the organization must import or request a TLS certificate in ACM or IAM, assign it to the ALB's HTTPS listener, and ensure the ALB's security group allows HTTPS traffic. The backend server does not need the same TLS certificate since the ALB performs TLS termination. SNI is only necessary when multiple TLS certificates are used for serving different domains.

  • A. Correct.

    Correct. The TLS certificate must be managed in AWS Certificate Manager (ACM) or uploaded into IAM so it can be assigned to the ALB.

  • B. Correct.

    Correct. The TLS certificate must be explicitly associated with the HTTPS listener of the ALB to serve HTTPS traffic.

  • C. Incorrect.

    Incorrect. The web application server does not need to have a copy of the TLS certificate because the ALB terminates HTTPS traffic and forwards it to the backend over HTTP or HTTPS as configured.

  • D. Correct.

    Correct. The security group associated with the ALB must allow inbound traffic on port 443 (HTTPS) to ensure secure communication.

  • E. Incorrect.

    Incorrect. Enabling Server Name Indication (SNI) is only necessary if the ALB is expected to serve multiple TLS certificates for different domains, which is not a requirement in this scenario.

Timed practice exam

Take a SCS-C02 practice test under exam conditions

65 questions in 170 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam